Cicada3301 is a ransomware-as-a-service group that emerged in 2024, suspected to be a successor of BlackCat/ALPHV.
Analyst brief
Cicada3301 is a ransomware-as-a-service group that emerged in mid-2024, suspected to be a successor of BlackCat/ALPHV. The group primarily targets Windows, Linux, and ESXi systems. Their key TTPs include Rust-based ransomware and an affiliate program with a 20% commission. Defenders should focus on Rust-based ransomware payloads, affiliate activity patterns, and indicators linked to BlackCat threat intelligence.
cicada3301
crime
Cicada3301 is a ransomware-as-a-service group (tracked as Repellent Scorpius by Palo Alto) that emerged in mid-2024 using Rust-based ransomware targeting Windows, Linux, and ESXi systems, suspected to be a successor of BlackCat/ALPHV and running an affiliate program with 20% commissions.